Ukrainian Institutions Targeted Using HATVIBE and CHERRYSPY MalwareThe Hacker News·Jul 24, 05:33 UTC · Jul 24, 2024MalwareCVE-2024-2369247
Vollgar botnet has managed to infect around 3k MSSQL DB servers dailySecurity Affairs·Apr 1, 15:50 UTC · Apr 1, 2020Malware42
WARNING: Hackers Install Secret Backdoor on Thousands of Microsoft SQL ServersThe Hacker News·Apr 1, 13:02 UTC · Apr 1, 2020Malware42
Chinese-Backed Silver Fox Plants Backdoors in Healthcare NetworksInfosecurity Magazine·Feb 25, 13:40 UTC · Feb 25, 2025Malware42
Stealth Falcon's undocumented backdoor uses Windows BITS to exfiltrate dataSecurity Affairs·Sep 24, 16:29 UTC · Sep 24, 2023Malware42
CRAT wants to plunder your endpointsCisco Talos·Nov 12, 13:18 UTC · Nov 12, 2020MalwareCVE-2017-829147
The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefactKaspersky Securelist·Jun 30, 08:00 UTC · Jun 30, 2022Malware42
OilRig Malware Campaign Updates Toolset and Expands TargetsPalo Alto Unit 42·Nov 1, 10:23 UTC · Nov 1, 2018Malware42
Cloud Atlas using a new backdoor, VBCloud, to steal dataKaspersky Securelist·Dec 23, 10:00 UTC · Dec 23, 2024MalwareCVE-2018-080247
GoPix banking Trojan targeting Brazilian financial institutionsKaspersky Securelist·Mar 16, 09:36 UTC · Mar 16, 2026Malware42
The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth BackdoorPalo Alto Unit 42·Nov 1, 10:15 UTC · Nov 1, 2018Malware42
South Korean ERP Vendor's Server Hacked to Spread Xctdoor MalwareThe Hacker News·Jul 3, 06:52 UTC · Jul 3, 2024Malware42
OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
Transparent Tribe Launches New RAT Attacks Against Indian Government and AcademiaThe Hacker News·Jan 6, 05:33 UTC · Jan 6, 2026Malware42
Two never-before-seen tools, from same group, infect airArs Technica · Security·Oct 9, 12:26 UTC · Oct 9, 2024Malware42
Chafer used Remexi malware to spy on IranKaspersky Securelist·Jan 30, 10:00 UTC · Jan 30, 2019Malware42
New MATA Multi-platform malware framework linked to NK Lazarus APTSecurity Affairs·Jul 23, 14:47 UTC · Jul 23, 2020Malware42
PlugX malware delivered by exploiting flaws in Chinese programsSecurity Affairs·Mar 11, 19:40 UTC · Mar 11, 2023Malware42
North Korea-linked Lazarus APT uses first Mac malware in cryptocurrency exchange attackSecurity Affairs·Aug 24, 15:17 UTC · Aug 24, 2018Malware42
New Tomiris tools and techniques: multiple reverse shells, Havoc, AdaptixC2Kaspersky Securelist·Nov 28, 07:00 UTC · Nov 28, 2025Malware142
Hackers Exploiting Remote Desktop Software Flaws to Deploy PlugX MalwareThe Hacker News·Mar 10, 06:46 UTC · Mar 10, 2023Malware42
Prometei botnet improves modules and exhibits new capabilities in recent updatesCisco Talos·Mar 9, 13:02 UTC · Mar 9, 2023MalwareCVE-2019-0708147
Prilex: Brazilian PoS malware evolutionKaspersky Securelist·Sep 29, 12:56 UTC · Sep 29, 2022Malware42
Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese TargetsPalo Alto Unit 42·Nov 1, 09:41 UTC · Nov 1, 2018Malware42
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Hacker News·Jul 28, 11:55 UTC · Jul 28, 2026Malware42
Researchers Uncover RAT-Dropping npm Package Targeting Gulp UsersThe Hacker News·Jun 4, 06:13 UTC · Jun 4, 2024Malware42
Highlighting TA866/Asylum Ambuscade Activity Since 2021Cisco Talos·Oct 23, 10:02 UTC · Oct 23, 2024Malware42
Chinese StormBamboo APT compromised ISP to deliver malwareSecurity Affairs·Aug 4, 21:00 UTC · Aug 4, 2024MalwareCVE-2021-3086947
High-profile malware and targeted attacks in Q1 2023Kaspersky Securelist·Jun 7, 08:00 UTC · Jun 7, 2023Malware42
BE2 custom plugins, router abuse, and target profilesKaspersky Securelist·Nov 3, 07:58 UTC · Nov 3, 2014Malware42
New 'HrServ.dll' Web Shell Detected in APT Attack Targeting Afghan GovernmentThe Hacker News·Nov 27, 06:30 UTC · Nov 27, 2023Malware42
Magnat campaigns use malvertising to deliver information stealer, backdoor and malicious Chrome extensionCisco Talos·Dec 2, 12:48 UTC · Dec 2, 2021Malware42
Tomiris called, they want their Turla malware backKaspersky Securelist·Apr 26, 07:40 UTC · Apr 26, 2023Malware42